Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
HIGH 7.5 CVE-2021-45100 The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabl… Ksmbd after 3.4.2 Fix from $1,9502021-12-16 MEDIUM 6.8 CVE-2021-44518 An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing code before each operation (… Egeetouch Manager No fix yet Fix from $1,6002021-12-02 HIGH 8.1 CVE-2021-44480 Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen to a device's surroundings v… Wokka Watch Q50 Firmware Mitigation only Fix from $1,9502021-12-01 MEDIUM 5.9 CVE-2021-38978 IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to pro… Security Guardium Key Lifecycle Manager after 4.0.0.3 Fix from $1,6002021-11-15 MEDIUM 5.3 CVE-2021-3792 Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the co… Halo\+ Camera Firmware 03.40.00 / 03.40.02+ Fix from $1,6002021-11-12 HIGH 7.4 CVE-2021-40366 A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module) (All versions < V11.34). Th… Climatix Pol909 Firmware 11.34 / 11.42+ Fix from $1,9502021-11-09 MEDIUM 5.9 CVE-2020-4152 IBM QRadar Network Security 5.4.0 and 5.5.0 transmits sensitive or security-critical data in cleartext in a communication channel that can be obtaine… Qradar Network Security 5.4.0.14 / 5.5.0.9+ Fix from $1,6002021-11-08 MEDIUM 6.5 CVE-2021-3774 Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security mea… Mss550x Firmware after 3.1.3 Fix from $1,6002021-11-05 MEDIUM 5.9 CVE-2021-29753 IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it… Business Automation Workflow Mitigation only Fix from $1,6002021-11-05 MEDIUM 5.9 CVE-2021-42699 The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can capture network traffic, obtain th… Daqfactory after 18.1 Fix from $1,6002021-11-05 MEDIUM 5.9 CVE-2021-38418 Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and pe… Dialink after 1.2.4.0 Fix from $1,6002021-11-03 HIGH 7.5 CVE-2021-43270 Datalust Seq.App.EmailPlus (aka seq-app-htmlemail) 3.1.0-dev-00148, 3.1.0-dev-00170, and 3.1.0-dev-00176 can use cleartext SMTP on port 25 in some ca… Seq.app.emailplus Patch available Fix from $1,9502021-11-02 HIGH 8.2 CVE-2021-39341EPSS 22% The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorizatio… Optinmonster after 2.6.4 Fix from $1,9502021-11-01 HIGH 7.4 CVE-2021-0296 The Juniper Networks CTPView server is not enforcing HTTP Strict Transport Security (HSTS). HSTS is an optional response header which allows servers … Ctpview Mitigation only Fix from $1,9502021-10-19 HIGH 7.5 CVE-2021-20599 Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/… R08sfcpu Firmware Mitigation only Fix from $1,9502021-10-14 MEDIUM 5.3 CVE-2021-39882 In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user. GitLab 14.1.7 / 14.2.5+ Fix from $1,6002021-10-05 HIGH 7.5 CVE-2020-20128 LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers. Laracms No fix yet Fix from $1,9502021-09-29 HIGH 7.5 CVE-2021-22946 A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the… Curl 7.79.0+ Fix from $1,9502021-09-29 HIGH 7.5 CVE-2021-39342 The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenev… Financial 1.4.9+ Fix from $1,9502021-09-29 MEDIUM 5.3 CVE-2021-36165 RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as ba… S9922l Firmware No fix yet Fix from $1,6002021-09-28 HIGH 8.1 CVE-2021-40847EPSS 10% The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root… R6400v2 Firmware No fix yet Fix from $1,9502021-09-21 HIGH 8.8 CVE-2021-38142 Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades. An attacker on the local network can achie… Mirrorop Windows Sender 2.5.3.65+ Fix from $1,9502021-09-07 MEDIUM 5.9 CVE-2021-39272 Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH. Fedora 6.4.22+ Fix from $1,6002021-08-30 HIGH 7.5 CVE-2021-33883 A Cleartext Transmission of Sensitive Information vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote attacker to obtain sensitiv… Spacecom2 012u000062+ Fix from $1,9502021-08-25 MEDIUM 5.3 CVE-2021-38373 In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" … Kmail Mitigation only Fix from $1,6002021-08-10 MEDIUM 5.3 CVE-2021-22923 When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those sam… Curl 1.0.1.1 / 7.78.0+ Fix from $1,6002021-08-05 HIGH 7.5 CVE-2021-33900 While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-… Directory Studio after 1.5.3 Fix from $1,9502021-07-26 HIGH 7.5 CVE-2020-36423 An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't prop… Debian Linux 2.16.7 / 2.23.0+ Fix from $1,9502021-07-19 MEDIUM 6.5 CVE-2020-4980 IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as wel… Qradar Security Information And Event Manager 7.3.3 / 7.4.3+ Fix from $1,6002021-07-16 MEDIUM 5.3 CVE-2020-12730 MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery. Flamingo 2 Firmware Mitigation only Fix from $1,6002021-07-15